Insecure Way to Upgrade to WordPress 2.3
As you may already know, WordPress 2.3 has been released yesterday and many folks around the world are sharing their upgrade experiences. The one that caught my attention was the “5 Step Failsafe upgrade for WordPress” published at BlogSecurity.
Not offense intended but I wonder why a blog dedicated to security recommends an insecure backup plugin that can allow anyone to download database backups or any file from the file system.
If you are planning to upgrade your WordPress blog, just try to do manual steps because many backup plugins are very insecure — if you still want to use some of them, deactivate it when the upgrade process is completed.
8 Responses to “Insecure Way to Upgrade to WordPress 2.3”
September 25th, 2007 at 10:43 am
Alex, why am I not surprised you have another vulnerability to share
Is the vul public?
September 25th, 2007 at 11:32 am
David, is not public yet, however I do not plan to write any advisory.
September 25th, 2007 at 1:08 pm
I hope you keep us in the loop champ! I think BlogSec may even sponsor this plugin, it may have some bugs, buts its an absolutely awesome project!
September 26th, 2007 at 12:32 am
Alex, BackUpWordPress is a beta release, I haven’t had too much support from experienced WordPress users until now. Please tell me more about the vulnerabilities you find in the plugin. Thanks a lot in advace!
September 26th, 2007 at 2:48 am
Alex, a bug-fix release of BackUpWordPress was released this moment. The plugin’s backup repository is now secured by .htaccess. I also have added capabilities to the Plugin, to allow the blog admin to download backup archives.
Thans a lot for pointing out security issues in BackUpWordPress!
September 26th, 2007 at 10:30 am
Well done Roland!, I didn’t answer before because I was sleeping
September 26th, 2007 at 3:55 pm
Alex, I’m happy to see some WordPress core developers having a look at my plugins. I have set up a forum (http://wpforum.designpraxis.at/) for support, bug reports, troubleshooting etc., if you happen to run into more security issues with my stuff, please let me know!
November 2nd, 2007 at 11:45 am
[...] has a fix for a very critical security vulnerability reported by Alexander Concha, who already helped before improving BackUpWordPress. Thanks [...]
Leave a Reply